Engage Benson

Personal Information

1 / 4
When does a data processor become a data controller?

When does a data processor become a data controller?

2 August 2026

Here is the story of Christine that I recently read from a determination by the Office of the Data Protection Commissioner. A representative from NSSF loved her YouTube channel and asked her to do a video interview about her retirement experience. The deal was a token appreciation fee of Ksh. 20,000. NSSF brought in a contractor, Off Grid Concepts Ltd, to do the filming.

The contractor filmed Christine at her home. She was shown the edit. She liked it. But she had never signed any indemnity form, and she had not given the final green light for it to be shown publicly.

One day during the launch of NSSF was launching its Strategic Plan, which was broadcasted live on national TV stations, NTV and KTN, Christine's interview video was played by Off Grid Concepts Ltd. She found out from a friend who called to congratulate her. She was shocked. She had not consented to that. She sued.

NSSF said they explicitly told the contractor not to air the video until it was properly edited and the indemnity was signed. The contractor, Off Grid Concepts, admitted it was a mistake. The Office of the Data Protection Commissioner had to answer one key question: Who between NSSF and the contractor was liable under the law?

The Anatomy of the Controller-Processor Relationship

Every day across Kenya, companies engage contractors, agencies, and service providers to handle personal data on their behalf. A bank hires a digital agency to create a customer testimonial video. A hospital engages a cloud service provider to store patient records. A university contracts a graduation photographer to capture images of students.

In each of these relationships, the law draws a clear line between two distinct actors. Under Section 2 of the Data Protection Act, 2019, a data controller means a natural or legal person which alone or jointly with others determines the purpose and means of processing of personal data. A data processor means a natural or legal person which processes personal data on behalf of the data controller.

In Christine's case, NSSF was the data controller. They decided why the video should be made and how it should be used. Off Grid Concepts was the data processor. They were hired to do the filming and editing on behalf of NSSF.

The Moment a Processor Becomes a Controller

Here is where the law creates a trap for the unwary processor. Section 42(3) of the Act provides that where a data processor processes personal data other than as instructed by the data controller, the data processor shall be deemed to be a data controller in respect of that processing.

When Off Grid Concepts aired the video without following NSSF's instructions, they stepped out of the processor role. They became a data controller for that specific action. They became solely responsible for the breach. Section 65(2)(b)(ii) of the Act reinforces this by holding processors liable for damage caused by the processing only if the processor has acted outside or contrary to the data controller's lawful instructions.

This principle appears repeatedly in ODPC determinations. In a recent case involving Artcaffe Coffee & Bakery, a complainant alleged that her image was used on billboards without proper consent. The 2nd Respondent successfully defended itself by demonstrating that while it provided branding for the billboards, it was not responsible for marketing in its partnership and was not privy to the arrangements between the complainant and other parties. The ODPC determined that the 2nd Respondent was a third party and dismissed the claim against it.

The lesson is clear. Liability follows control. When you step outside your instructions, you assume the full weight of controller obligations.

The Consent Question That Underpins Everything

The ODPC examined whether this was a commercial purpose violation under Section 37(1) of the Act. That section requires express consent before using personal data for commercial gain. The office found that because the video did not promote the contractor's own goods or services, it did not meet the definition of commercial use under Regulation 14(1) of the General Regulations.

However, the core violation remained the lack of consent. Section 30(1)(a) of the Act requires consent for processing. It states that a data controller or data processor shall not process personal data unless the data subject consents to the processing for one or more specified purposes. Section 2 of the Act defines consent as any manifestation of express, unequivocal, free, specific and informed indication of the data subject's wishes by a statement or by a clear affirmative action.

In Christine's case, that consent was never given. She had not signed the indemnity form. She had not given the final green light. The processing happened without her agreement.

The ODPC also found a violation of Section 25 of the Act, which sets out the principles of data protection. The fairness principle requires a person to handle personal data in ways the data subject would reasonably expect. Christine expected her video to be used only after she signed the form. Using it before then was fundamentally unfair.

The Worldcoin case from the High Court of Kenya reinforces these principles. The court found that Worldcoin's consent was induced through offering approximately KES. 7,000 to data subjects who could not withdraw their consent without losing the Worldcoin token. The High Court held that the consent was not free, specific and informed as required under Section 2 of the Act. The court emphasized that luring vulnerable people with cryptocurrency bypasses the essence of informed consent.

The Outcome That Reshapes Liability

The outcome in Christine's case was a clear separation of liability. The complaint against NSSF was dismissed. They had given clear instructions and could not be held responsible for a processor who ignored them. Off Grid Concepts was found liable and ordered to pay Ksh. 450,000 compensation.

This determination echoes a broader principle emerging from ODPC decisions. In a recent case, the ODPC found that where a data subject is not informed of the specific purpose for which their personal data is to be used and to whom the said personal data will be transferred, their consent will be deemed invalid under the Act.

Real World Scenarios Where Disputes Arise

The controller-processor dynamic creates friction points in countless everyday situations. Consider these scenarios.

A company hires a marketing agency to run a social media campaign. The agency uses customer images beyond the scope of the contract. Who is liable when a customer complains?

A hospital engages an IT firm to manage patient records. The IT firm experiences a data breach because its staff accessed records without authorization. The hospital faces regulatory action while the IT firm argues it was merely following instructions.

A university contracts a graduation photographer. The photographer uses student images in their own portfolio and marketing materials without obtaining separate consent. Students object to their images being used to promote a commercial business.

A property management company installs CCTV cameras and hires a security firm to monitor them. The security firm shares footage with third parties without the property company's knowledge or consent.

In each of these scenarios, the same legal principles apply. The controller determines the purpose and means. The processor acts on instructions. When the processor steps outside those instructions, they become a controller for that processing and assume sole liability.

The Contractual Shield: Data Processing Agreements

This is where the law meets the practical reality of business relationships. Regulation 24 of the Data Protection (General) Regulations, 2021 requires that where a controller engages a processor, there must be a legally binding contract governing the processing.

A Data Processing Agreement serves several critical functions. It documents the instructions given to the processor. It imposes confidentiality obligations. It requires security safeguards. It governs sub-processing arrangements. It provides for audit and inspection rights. It addresses end-of-contract data handling .

The agreement must include specific details about the processing. The subject matter. The duration. The nature and purpose. The type of personal data. The categories of data subjects. These elements ensure that both parties understand the scope of the processor's authority.

Critically, the agreement must address what happens when the processor needs to engage sub-processors. In Christine's case, Off Grid Concepts had a technical team that accessed the folder and aired the video without proper briefing. A robust DPA would require prior authorization before any sub-processor is engaged and would impose contractual obligations on the processor to ensure its personnel understand and comply with instructions.

The agreement must also include mechanisms for the controller to audit the processor's compliance. Section 23 of the Act provides for compliance and audit obligations. A well-drafted DPA gives the controller the right to inspect the processor's systems, policies, and practices to ensure they align with the controller's instructions and the law.

Data Sharing Agreements: When Controllers Share

Sometimes the relationship is not controller-processor but controller-to-controller. Two independent entities each determine their own purposes for processing. They share data for their respective purposes.

A Data Sharing Agreement governs this type of relationship. It defines the parties. It sets out the purpose and lawful basis for sharing. It identifies the categories of data. It addresses data subject rights. It specifies processing and security details. It establishes retention and deletion procedures. It clarifies that ownership is not transferred.

The key difference from a DPA is accountability. In a controller-processor relationship, the controller remains primarily accountable. In a controller-to-controller relationship, both parties are independently accountable for their own processing.

Consider a hospital sharing patient data with a medical research institute. The hospital processes data for treatment purposes. The research institute processes data for scientific study. Each has its own lawful basis and its own purposes. A DSA ensures both parties understand their respective obligations and that data subjects are properly informed.

The Sub-Processor Problem

Christine's case highlights a common vulnerability. Off Grid Concepts had a technical team that accessed the folder and made an assumption about what should be aired. The director admitted that he did not brief his team appropriately not to air the clip.

Under the Act, a processor remains responsible for the actions of its personnel and any sub-processors it engages. Regulation 24 requires that where a processor engages another processor, this must be done only with the prior authorization of the controller. The processor must impose the same data protection obligations on the sub-processor as are contained in the DPA.

Many organizations overlook this requirement. They assume that their employees and contractors are covered by the main agreement. But the law requires explicit authorization and contractual flow-down of obligations. Failure to comply leaves the processor liable for any breaches caused by sub-processors.

The Notification Obligation

When a breach occurs, timing matters. Regulation 20 of the General Regulations requires data controllers and processors to notify the ODPC within seventy-two hours if the breach poses a real risk of harm to the data subject. This includes instances where the breach has occasioned unauthorized disclosure of a data subject's full name, password, security codes, or access codes.

In Christine's case, the video was aired during a live broadcast on national television. The breach was immediate and widespread. The notification obligation would have triggered within hours. Failure to notify can result in additional penalties under Section 63 of the Act, which provides for administrative fines.

Strategies for Controllers

Controllers must take proactive steps to protect themselves. Document every instruction given to processors. Maintain a paper trail of communications. Require processors to acknowledge and confirm understanding of instructions. Conduct due diligence on processors before engagement. Verify that processors have appropriate policies, training, and security measures. Include robust audit rights in DPAs and exercise them. Require processors to notify immediately of any actual or suspected breaches. Ensure processors have mechanisms to obtain and verify consent from data subjects.

In the Artcaffe case, the 2nd Respondent successfully defended itself by demonstrating that it was not responsible for marketing and was not privy to the arrangements between the complainant and other parties . The lesson for controllers is clear. Define roles precisely. Document everything. Ensure everyone understands who is responsible for what.

Strategies for Processors

Processors cannot afford to be passive. Understand the scope of your instructions. If instructions are unclear, seek clarification. Do not assume. Document all communications with the controller. Train your personnel on data protection obligations. Ensure everyone understands the limits of their authority. Implement technical measures to prevent unauthorized processing. Restrict access to data based on need and authorization. Verify consent before using any personal data. Do not rely on the controller's assurances. Obtain and document consent independently. Have clear procedures for handling data subject requests. Notify controllers immediately of any actual or suspected breaches. Maintain records of processing activities. In Christine's case, the director admitted his mistake and took responsibility. But admission of error does not negate liability. The ODPC still ordered compensation. Processors must understand that good faith and honesty are not defenses to unlawful processing.

The Commercial Purpose Distinction

The ODPC found that Off Grid Concepts did not violate the commercial use provisions because the video did not promote the contractor's own goods or services. This distinction matters for businesses that use personal data for marketing, advertising, or promotional activities. Section 37(1) of the Act requires express consent before using personal data for commercial purposes. Regulation 14(1) of the General Regulations defines commercial purposes to include using personal data to advance commercial or economic interests, including inducing another person to buy, rent, lease, join, subscribe to, provide or exchange products, property, or services.

For processors who use data to promote their own business, this is a critical compliance point. If Off Grid Concepts had used Christine's video on their own website or in their own marketing materials, they would have faced additional liability under Section 37. The absence of that element limited the violation to unlawful processing rather than commercial use.

The Compensation Question

Christine prayed for compensation of not less than Ksh. 5 million. The ODPC declined to award this amount, finding it inordinately high and an erroneous estimate of the damage. Instead, the office ordered Ksh. 450,000, taking into consideration the scope of publication and the fact that the video was played on various national TV stations.

Section 65 of the Act provides that a person who suffers damage by reason of a contravention of a requirement of the Act is entitled to compensation for that damage from the data controller or data processor. Regulation 14(3)(e) of the Enforcement Regulations provides that the Data Commissioner may make an order for compensation to the data subject by the respondent.

The ODPC's approach to compensation considers several factors. The nature and gravity of the breach. The scope of publication or disclosure. The impact on the data subject. The conduct of the respondent. Any mitigating actions taken.

For data subjects, this means that compensation is not automatic and not limitless. The ODPC will assess each case on its merits and award compensation based on the actual damage suffered.

The Emerging Jurisprudence

The ODPC and Kenyan courts are building a body of decisions that clarify the controller-processor relationship. The Worldcoin case from the High Court is particularly instructive. The court found that Worldcoin violated the law by collecting biometric data without an adequate Data Protection Impact Assessment, using induced consent, transferring data cross-border without safeguards, and failing to register properly as data controllers and processors.

The court issued several orders. A prohibition order prevented further collection, processing, or transfer of biometric data without compliance. An order of certiorari quashed prior data collection decisions made in violation of the law. An order of mandamus compelled Worldcoin to permanently destroy or erase the biometric data collected from Kenya . These orders demonstrate the range of remedies available when data protection laws are violated. Compensation is one remedy, but injunctive relief and corrective orders are equally important tools for protecting data subject rights.

Practical Steps for Compliance

Organizations that handle personal data must take concrete steps to comply with the Act and avoid the fate that befell Off Grid Concepts. Register with the ODPC. Section 18 of the Act requires data controllers and processors to register. The Registration Regulations set out the categories of entities that must register and the exemptions that apply. Conduct Data Protection Impact Assessments for high-risk processing. Section 31 requires a DPIA where processing is likely to result in high risk to data subject rights. Biometric data, genetic data, and sensitive personal data typically require a DPIA.

Implement data protection by design and default. Section 41 requires controllers and processors to implement appropriate technical and organizational measures to integrate data protection safeguards into processing activities.

Develop and maintain policies. The General Regulations require data controllers and processors to develop, publish, and regularly update policies reflecting their personal data handling practices. Train personnel. Ensure that everyone who handles personal data understands their obligations under the Act. In Christine's case, a simple briefing could have prevented the entire incident.

Document everything. Maintain records of processing activities, consent obtained, instructions given, and actions taken. Documentation is your best defense when disputes arise.

Conclusion

Christine’s case is not an isolated incident. It is a window into the complex dynamics that arise whenever organizations handle personal data through third parties. The controller-processor relationship is fundamental to the data protection framework, but it is also a source of significant risk when not properly managed.

The lessons from this determination extend far beyond the specific facts:

  1. Controllers must document their instructions and verify compliance.

  2. Processors must understand their independent obligations and ensure they have proper consent before acting.

  3. Both parties must recognize that when a processor steps outside instructions, they become solely liable for the resulting breach.

  4. A properly drafted Data Processing Agreement is mandatory.

  5. Consent must be obtained before processing, not after.

  6. The fairness principle requires processing personal data in ways the data subject would reasonably expect.

  7. Sub-processors must be authorized and bound by the same obligations.

  8. Breach notification must occur within seventy-two hours.

  9. Compensation is not automatic and will be assessed based on the actual damage suffered.

For content creators, marketers, agencies, and businesses of all types, the message is clear. Consent is not optional. Instructions matter. Documentation saves you. And the law will hold you accountable when you get it wrong.

These liabilities are real. Your service agreements and data protection practices must anticipate them or they may devour your business. Review your contracts with me to scan for data compliance, indemnity, risk allocation, and proper controller-processor provisions.

By: Benson Odiwuor

Advocate of The High Court of Kenya


Should you have any questions regarding the subject, reach out at insights@bensonodiwuor.com

Found this useful? Share it with a colleague.

Share
All posts

Legal counsel, research collaboration, or speaking inquiries.

Engage Benson

Personal Information

1 / 4